Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25592
Total
1903
Critical
7807
High
8024
Medium
CVE ID Severity Score Description Published
CVE-2026-45582 MEDIUM 6.5 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could … May 29, 2026
CVE-2026-45580 MEDIUM 5.4 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders … May 29, 2026
CVE-2026-45578 HIGH 8.8 WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds … May 29, 2026
CVE-2026-45555 HIGH 7.8 Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads … May 29, 2026
CVE-2026-44698 HIGH 8.3 Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he … May 29, 2026
CVE-2026-44239 UNKNOWN FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input … May 29, 2026
CVE-2026-44238 UNKNOWN FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort … May 29, 2026
CVE-2026-44237 UNKNOWN FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. … May 29, 2026
CVE-2026-40528 LOW 3.8 OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to … May 29, 2026
CVE-2026-40510 LOW 3.8 OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trigger memory … May 29, 2026
CVE-2026-10075 MEDIUM 5.3 DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path … May 29, 2026
CVE-2026-10074 MEDIUM 4.9 DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files. May 29, 2026
CVE-2026-10073 HIGH 7.5 DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files. May 29, 2026
CVE-2026-10072 HIGH 7.2 DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code … May 29, 2026
CVE-2026-10061 MEDIUM 6.3 A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in … May 29, 2026
CVE-2026-10060 MEDIUM 6.3 A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads … May 29, 2026
CVE-2026-9509 UNKNOWN An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service … May 29, 2026
CVE-2026-9508 UNKNOWN Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the … May 29, 2026
CVE-2026-8326 UNKNOWN Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected … May 29, 2026
CVE-2026-49324 MEDIUM 4.6 Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with … May 29, 2026
CVE-2026-49323 MEDIUM 4.3 Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year … May 29, 2026
CVE-2026-48527 HIGH 8.7 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) … May 29, 2026
CVE-2026-45611 UNKNOWN Rejected reason: Further research determined the issue is not a vulnerability. May 29, 2026
CVE-2026-45551 UNKNOWN Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings … May 29, 2026
CVE-2026-45312 CRITICAL 9.9 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated user … May 29, 2026